PolyglotDuke is a Windows first-stage implant and downloader associated with APT29, also known as the Dukes or Cozy Bear, and was used in the long-running espionage campaign known as Operation Ghost. It has been observed targeting high-value diplomatic and government entities, including European ministries of foreign affairs and an embassy in Washington, DC. The malware forms part of a staged intrusion platform in which it serves as an initial foothold and command-and-control discovery component before follow-on payloads are deployed.
PolyglotDuke is notable for its stealth-oriented command-and-control discovery methods. It can obtain command-and-control URLs from public web services including social media and image-hosting platforms, and it can use steganography to conceal command-and-control information within images. The malware also uses custom string decryption routines and stores encrypted JSON configuration data in the Windows Registry, reflecting an emphasis on obfuscation and low-visibility local storage.
Execution behavior includes use of Windows mechanisms such as rundll32 as well as API-driven loading and process creation through functions including LoadLibraryW and CreateProcess. These traits align with its role as a lightweight staging implant designed to retrieve and launch additional malicious components while minimizing overt artifacts. PolyglotDuke has also been linked through code and tradecraft similarities to earlier Dukes malware families, reinforcing its place within APT29’s long-running espionage toolset.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This held true until recent months, when we uncovered three new malware families that we attribute to the Dukes – PolyglotDuke, RegDuke and FatDuke.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The Dukes encrypts PolyglotDuke and LiteDuke payloads with custom algorithms. They also rely on known obfuscation techniques such as opaque predicates and control flow flattening to obfuscate RegDuke, MiniDuke and FatDuke.
Examples include: “ComRAT has encrypted and stored its orchestrator code in the Registry…”, “ShadowPad maintains a configuration block and virtual file system in the Registry.”, and “QakBot can store its configuration information…under HKCU\Software\Microsoft.”
Command and Control T1001 Data Obfuscation The Dukes use steganography to hide payloads and commands inside valid images.
Command and Control T1008 Fallback Channels The Dukes have multiple C&C servers in case one of them is down.
Command and Control T1071 Standard Application Layer Protocol The Dukes are using HTTP and HTTPS protocols to communicate with the C&C server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT29 malware strain used in Operation Ghost.
Malware that uses a custom algorithm to decrypt strings.
Malware that uses LoadLibraryW and CreateProcess to load and execute code.
Backdoor that writes encrypted JSON configuration data into the Registry.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.